Two-Factor TOTP Authentication

Protect access to your data with TOTP two-factor authentication. Mandatory or optional according to your policies.

Hextal two-factor authentication (2FA) is based on the TOTP (Time-based One-Time Password) standard, the same protocol used by Google Authenticator, Authy, FreeOTP and most password managers. After entering their password, the user must provide a temporary 6-digit code generated by their authentication app, renewed every 30 seconds.

2FA activation is flexible: you can make it mandatory for all users, for certain roles only (administrators, managers, external access), or offer it as an option. Configuration is done via security policy at the tenant level, with granularity by workspace or by access type (e.g. 2FA mandatory for remote access, optional for access from the internal network).

In addition to TOTP, Hextal supports FIDO2/WebAuthn security keys (YubiKey, Titan, biometric keys) for the most demanding environments. Account recovery methods are secured: single-use backup codes, administrator verification, or authentication via the EUDI Wallet for users who have one.

Benefits

Anti-Phishing Protection

Even if a password is compromised, the second factor blocks access. Phishing becomes ineffective.

Universal Standard

TOTP is compatible with all authentication apps (Google Auth, Authy, 1Password, Bitwarden).

Flexible Policy

Mandatory for all, per role, per access type or per workspace. You define the security level suited to your context.

FIDO2/WebAuthn Support

For sensitive environments, support for physical security keys (YubiKey) and biometrics (Windows Hello, Touch ID).

Use Cases

Try Hextal →